FOI Request

Dave Schneider made this Freedom of Information request to Aberdeen City Council

The request was successful.

From: Dave Schneider

13 August 2010

Sir/Madam,

I wish to make a request under the Freedom of Information Act. The
following questions and information I wish to have sent to me are
as follows:

Provide, name, address and telephone number for the following
people:
• Senior Information Risk Owner
• Governance Manager
• Information Security Officer/Manager
• Information Technology Security Officer/Manager
• Caldecott Guardian

PCI-DSS
Does your organisation process electronic payment cards?
How much money is processed from electronic payment cards per
annum?
How many electronic payment card transactions are processed per
annum?
Are you PCI-DSS compliant?

ISO 27001
Are you or have you considered becoming ISO 27001 compliant or
certified?

Government Connect
Are you connected and operationally utilising the Government
Connect network? If not have you considered connecting to
Government Connect and why was the decision made not to connect?
Do you meet the Government Connect version three requirements?
Please supply your latest CLAS consultant annual Government Connect
assessment/audit report, blanking out any statements which could
contravene a security concern from a third party reading it.
Do you meet the Government Connect version four requirements?
Please supply the latest internal report for the Government Connect
version four Audit/Assessment, blanking out any statements which
could contravene a security concern from a third party reading it.

Criminal Justice Network
Are you connected to and operationally utilising the Criminal
Justice Network? If not have you considered connecting to the
Criminal Justice Network and why was the decision made not to
connect?
Please supply your latest annual assessment/audit report, blanking
out any statements which could contravene a security concern from a
third party reading it.

NHS N3 Network
Are you connected to and operationally utilising the NHS N3
Network? If not have you considered connecting to the NHS N3
network and why was the decision made not to connect?
Please supply your latest N3 Connection assessment/audit report,
blanking out any statements which could contravene a security
concern from a third party reading it.
Do both schools and the Council share the same physical network
responsible for voice and data communications?

Yours faithfully,

Dave Schneider

Link to this

From: Foi Enquiries
Aberdeen City Council

16 August 2010

Dear Mr Schneider,

Freedom of Information enquiry reference ENQ9222.

Thank you for your request for information under the Freedom of
Information (Scotland) Act 2002 received on 16 August 2010, which has
been forwarded to the relevant section.

The scheduled date for our response to your request for information is
13 September 2010.

If you have any enquiries meantime please do not hesitate to contact
us.

Yours sincerely,

Kirsty Clark
FOI Compliance Assistant

FoI Enquiries Team
Legal and Democratic Services
Corporate Governance
Aberdeen City Council
Town House
Broad Street
Aberdeen AB10 1AQ
Tel: 01224 522875/523827
Fax: 01224 638556
email: [Aberdeen City Council request email]

show quoted sections

13/08/2010 17:04 >>>
Sir/Madam,

I wish to make a request under the Freedom of Information Act.
The
following questions and information I wish to have sent to me are
as follows:

Provide, name, address and telephone number for the following
people:
● Senior Information Risk Owner
● Governance Manager
● Information Security Officer/Manager
● Information Technology Security Officer/Manager
● Caldecott Guardian

PCI-DSS
Does your organisation process electronic payment cards?
How much money is processed from electronic payment cards per
annum?
How many electronic payment card transactions are processed per
annum?
Are you PCI-DSS compliant?

ISO 27001
Are you or have you considered becoming ISO 27001 compliant or
certified?

Government Connect
Are you connected and operationally utilising the Government
Connect network? If not have you considered connecting to
Government Connect and why was the decision made not to connect?
Do you meet the Government Connect version three requirements?
Please supply your latest CLAS consultant annual Government
Connect
assessment/audit report, blanking out any statements which could
contravene a security concern from a third party reading it.
Do you meet the Government Connect version four requirements?
Please supply the latest internal report for the Government
Connect
version four Audit/Assessment, blanking out any statements which
could contravene a security concern from a third party reading
it.

Criminal Justice Network
Are you connected to and operationally utilising the Criminal
Justice Network? If not have you considered connecting to the
Criminal Justice Network and why was the decision made not to
connect?
Please supply your latest annual assessment/audit report,
blanking
out any statements which could contravene a security concern from
a
third party reading it.

NHS N3 Network
Are you connected to and operationally utilising the NHS N3
Network? If not have you considered connecting to the NHS N3
network and why was the decision made not to connect?
Please supply your latest N3 Connection assessment/audit report,
blanking out any statements which could contravene a security
concern from a third party reading it.
Do both schools and the Council share the same physical network
responsible for voice and data communications?

Yours faithfully,

Dave Schneider

show quoted sections

Link to this

From: Foi Enquiries
Aberdeen City Council

8 September 2010

Dear Mr Schneider,

Thank you for your information request of 16 August 2010, made under
the Freedom of Information (Scotland) Act 2002 (FOISA). Aberdeen City
Council (ACC) has completed the necessary search for the information
requested.

I wish to make a request under the Freedom of Information Act. The
following questions and information I wish to have sent to me are as
follows:
Provide, name, address and telephone number for the following people:
● Senior Information Risk Owner
No formal post within ACC - covered by
Paul Fleming
Head of Customer Service and Performance
Corporate Governance
Aberdeen City Council
Ground Floor, St Nicholas House
Broad Street
Aberdeen
AB10 1GZ
Tel: 01224 523366

● Governance Manager
Stewart Carruth
Director of Corporate Governance
3rd Floor
Town House Extension
Broad Street
Aberdeen
AB10 1AQ
Tel: 01224 522550

● Information Security Officer/Manager
Bob Guild
ICT Security Manager
Operations' Security Team
Customer Service and Performance
Corporate Governance
Aberdeen City Council
6th Floor, St Nicholas House
Broad Street
ABERDEEN
AB10 1WL
Tel: 01224 522182

● Information Technology Security Officer/Manager
Bob Guild
ICT Security Manager
Operations' Security Team
Customer Service and Performance
Corporate Governance
Aberdeen City Council
6th Floor, St Nicholas House
Broad Street
ABERDEEN
AB10 1WL
Tel: 01224 522182

● Caldecott Guardian - Social Work
This is lead by NHS Grampian and Aberdeenshire Council not ACC.

PCI-DSS
Does your organisation process electronic payment cards?
Yes

How much money is processed from electronic payment cards per annum?
£26.4 Million.

How many electronic payment card transactions are processed per annum?
199453

Are you PCI-DSS compliant?
Yes

ISO 27001
Are you or have you considered becoming ISO 27001 compliant or
certified?
We are not ISO 27001 certified but have considered compliance and use
the principles within our ICT Security Strategy and Policies .

Government Connect
Are you connected and operationally utilising the Government Connect
network? If not have you considered connecting to Government Connect and
why was the decision made not to connect?
Do you meet the Government Connect version three requirements?
Please supply your latest CLAS consultant annual Government Connect
assessment/audit report, blanking out any statements which could
contravene a security concern from a third party reading it.
Do you meet the Government Connect version four requirements?
Please supply the latest internal report for the Government Connect
version four Audit/Assessment, blanking out any statements which could
contravene a security concern from a third party reading it.
We are not connected to Government Connect, as this service is for
English and Welsh Local Authorities. We are alternatively connected to
GSX and fulfill all the requirements of that secure-network service.

Criminal Justice Network
Are you connected to and operationally utilising the Criminal Justice
Network? If not have you considered connecting to the Criminal Justice
Network and why was the decision made not to connect?
Please supply your latest annual assessment/audit report, blanking out
any statements which could contravene a security concern from a third
party reading it.
We are not connected to the Criminal Justice Network. Systems which
might be considered appropriate to using that network are linked via
GSX.

NHS N3 Network
Are you connected to and operationally utilising the NHS N3 Network? If
not have you considered connecting to the NHS N3 network and why was the
decision made not to connect?
Please supply your latest N3 Connection assessment/audit report,
blanking out any statements which could contravene a security concern
from a third party reading it.
No, we do not connect to NHS N3 as this only applies to England and
Wales

Do both schools and the Council share the same physical network
responsible for voice and data communications?
Yes

We hope this helps with your request.

Yours sincerely,

Jean Reid
FOI Compliance Officer (Acting)

FURTHER INFORMATION

If you are unhappy with the response to your request for information,
or the way in which your request has been handled, you can submit a
complaint or request a review of our response. You should do this by 8
November 2010. To complain or request a review, write to:

City Archivist
Legal and Democratic Services
Aberdeen City Council
Old Town House
Broad Street
Aberdeen
AB10 1AQ
[email address]

Your request for review must include your name, an address, and your
reason(s) for requesting a review. You should also include the reference
number for your original request for information.

If you are not satisfied with the outcome of your request for review,
you can apply directly to the Office of the Scottish Information
Commissioner (OSIC) for a decision. Generally, OSIC cannot make a
decision unless you have been through the Council’s review procedure.
The Scottish Information Commissioner can be contacted at:

The Office of the Scottish Information Commissioner
Kinburn Castle
Doubledykes Road
St Andrews
Fife
KY16 9DS
www.itspublicknowledge.info

FoI Enquiries Team
Legal and Democratic Services
Corporate Governance
Aberdeen City Council
Town House
Broad Street
Aberdeen AB10 1AQ
Tel: 01224 522875/523827
Fax: 01224 638556
email: [Aberdeen City Council request email]

show quoted sections

Link to this

Things to do with this request

Anyone:
Aberdeen City Council only: